CVE-2026-32201
vulnerability analysis and mitigation

Overview

CVE-2026-32201 is an improper input validation vulnerability in Microsoft SharePoint Server that allows unauthenticated, network-based attackers to perform spoofing attacks. Disclosed on April 14, 2026, as part of Microsoft's April Patch Tuesday, it affects SharePoint Server 2016 (Enterprise), 2019, and Subscription Edition (versions prior to 16.0.19725.20210). It carries a CVSS v3.1 base score of 6.5 (Medium), though it was actively exploited as a zero-day at the time of disclosure (MSRC Advisory, CISA KEV, GitHub Advisory).

Technical details

The vulnerability is classified under CWE-20 (Improper Input Validation), meaning SharePoint Server fails to adequately validate attacker-supplied input before processing it. This allows an unauthenticated remote attacker to craft malicious network requests that cause SharePoint to misrepresent the source or authenticity of content or communications — a spoofing attack. No user interaction is required, and the attack complexity is low, making it trivially exploitable over the network. Specific vulnerable endpoints and payload details have been documented by threat researchers, with one source noting particular SharePoint URL paths being actively targeted (Duggan USA, Security Boulevard).

Impact

Successful exploitation allows an unauthenticated attacker to impersonate legitimate SharePoint content or communications, potentially deceiving users into trusting malicious data, disclosing credentials, or taking actions under false pretenses. The confidentiality and integrity impacts are both rated Low in the CVSS scoring, with no direct availability impact; however, in practice, exploitation has been linked to credential theft and data exfiltration as attackers leverage spoofed content to harvest sensitive information (Feedly Intelligence, CISA KEV). Over 1,370 internet-facing SharePoint servers were identified as still unpatched and actively targeted weeks after the patch was released, amplifying the organizational risk (BleepingComputer, eSecurity Planet).

Exploitability

CVE-2026-32201 was actively exploited in the wild at the time of disclosure and was added to CISA's Known Exploited Vulnerabilities (KEV) catalog on April 14, 2026, with a remediation due date of April 28, 2026 (CISA KEV). A public proof-of-concept exploit was published on GitHub (github.com/B1tBit/CVE-2026-32201-exploit) approximately one week after the patch release, further lowering the barrier to exploitation (Feedly Intelligence). The EPSS score is approximately 2.05% per Feedly data, though the GitHub Advisory Database reported a notably higher 7.891% (92nd percentile) at time of publication. No specific threat actor attribution has been publicly confirmed, and its connection to ransomware campaigns is listed as "Unknown" in the KEV catalog (CISA KEV).

Exploitation steps

  1. Reconnaissance: Use tools such as Shodan, Censys, or Shadowserver data to identify internet-facing Microsoft SharePoint Server 2016, 2019, or Subscription Edition instances that have not applied the April 2026 security update.
  2. Identify vulnerable endpoints: Target known SharePoint URL paths susceptible to the improper input validation flaw. Researchers have documented specific paths being actively probed in the wild (Duggan USA).
  3. Craft malicious request: Send a specially crafted HTTP request to the vulnerable SharePoint endpoint without authentication, supplying input that bypasses server-side validation checks.
  4. Trigger spoofing: The server processes the malformed input and returns or presents content that appears to originate from a legitimate source, enabling the attacker to impersonate trusted SharePoint communications or content.
  5. Harvest credentials or data: Leverage the spoofed content to deceive authenticated users into submitting credentials, clicking malicious links, or disclosing sensitive information — enabling credential theft and potential lateral movement within the organization (Security Boulevard, Feedly Intelligence).

Indicators of compromise

  • Network: Unusual or high-volume unauthenticated HTTP/HTTPS requests to SharePoint Server endpoints, particularly from external IP addresses; outbound connections from SharePoint servers to unknown external hosts following suspicious inbound requests.
  • Logs: SharePoint ULS (Unified Logging Service) logs showing repeated requests to specific vulnerable URL paths with anomalous or malformed input parameters; IIS access logs with unexpected 200 responses to unauthenticated requests targeting SharePoint endpoints.
  • File System: Unexpected files or scripts written to SharePoint directories following exploitation attempts; new or modified web.config files.
  • Process/Behavior: Unusual child processes spawned by SharePoint worker processes (w3wp.exe); evidence of credential harvesting tools or data staging activity on SharePoint servers post-exploitation.
  • Threat Intelligence: Presence of the GitHub PoC repository (github.com/B1tBit/CVE-2026-32201-exploit) in network traffic or endpoint telemetry (Duggan USA, BleepingComputer).

Mitigation and workarounds

Microsoft released patches on April 14, 2026, as part of the April Patch Tuesday update. Organizations should apply the following fixed versions immediately: SharePoint Server Subscription Edition (update to 16.0.19725.20210 or later), SharePoint Server 2019 (update to 16.0.10417.20114 or later), and SharePoint Enterprise Server 2016 (update to 16.0.5548.1003 or later) (MSRC Advisory). If immediate patching is not possible, implement network-level controls to restrict unauthenticated external access to SharePoint endpoints, and review SharePoint access logs for signs of spoofing activity. CISA's BOD 22-01 requires federal agencies to remediate this vulnerability by April 28, 2026 (CISA KEV).

Community reactions

The vulnerability received significant attention from the security community given its zero-day status and active exploitation at the time of disclosure. Tenable's Satnam Narang highlighted CVE-2026-32201 as a key vulnerability in Microsoft's April 2026 Patch Tuesday, which was described as one of the largest patch releases on record (Tenable Blog). Krebs on Security, The Hacker News, BleepingComputer, The Register, and Dark Reading all covered the vulnerability prominently, with several noting the unusual combination of a medium CVSS score and active zero-day exploitation (KrebsOnSecurity, The Hacker News). The Shadowserver Foundation and security researchers on Bluesky and Mastodon flagged the large number of unpatched internet-exposed SharePoint servers still vulnerable weeks after the patch release, generating community urgency around remediation (BleepingComputer). Rapid7 and Sophos also published detailed patch Tuesday analyses covering this CVE (Rapid7 Blog, Sophos Blog).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management